Getting started with 1Password for your growing team, or refining your setup? Our Secured Success quickstart guide is for you.
Forum Discussion
sj0123
2 years agoOccasional Contributor
Feature request: a separate vault with different access methods within a 1password account.
Hello.
I'm a fan of 1password.
This amazing service changed my digital life, I don't ever need to memorize or go threw password reset cycles all the time thanks to it.
However, having to type m...
sj0123
2 years agoOccasional Contributor
Hello Dave!
Thank you for the kind answer.
I wonder if the web app uses the same strong security model as the desktop apps and browser extensions, since web based cryptography libraries are quite limited compared to their native counterparts.
I'm also especially concerned about some javascript stealing data entered in form fields without my knowledge, as the web environment itself doesn't provide a secure sandbox.
And lastly, just out of curiosity, I grabbed up wireshark, decrypted TLS by telling my browser to save the session key and used that to see what packets are traveling over the network.
Among many things, I've spotted something like the address googleapis.com and the word password leak check, just after authentication finished with 1password.
If I remember correctly, there was a client id and client secret field being sent to googleapis.com in the form of JSON.
I truely don't know about this password leak check in chrome, so I'm worried about the possibility that the hash of my master password and secret key being sent to google for comparing against their database of leaked passwords.
If you can clarify these, I would truely appreciate it.
Please forgive me if I mistaken something in my post.
Thank you in advance.